The UN Cybercrime Treaty is Final, Here's What You Need to Know

Kurt Opsahl (Policy Counsel · Filecoin Foundation)

ShmooCon XX (Final) · Day 3 · Bring It On

Overview

Kurt Opsahl's ShmooCon talk, "The UN Cybercrime Treaty is Final, Here's What You Need to Know," provides a critical analysis of the newly finalized United Nations Convention on Cybercrime. This treaty, initiated in 2019 at the behest of Russia and China, aims to either supersede or significantly expand upon the existing Budapest Convention on Cybercrime. Opsahl, an internet lawyer with extensive experience at the Electronic Frontier Foundation (EFF) and the Filecoin Foundation, dissects the treaty's provisions, highlighting its profound implications for civil liberties, human rights, and the crucial work of independent security researchers globally.

Watch on YouTube

Visual summary for The UN Cybercrime Treaty is Final, Here's What You Need to Know by Kurt Opsahl
Visual summary for The UN Cybercrime Treaty is Final, Here's What You Need to Know by Kurt Opsahl

Key moments

  1. 0:00 Introduction and UN Cybercrime Treaty overview
  2. 2:00 How the UN Cybercrime Treaty started and key debates
  3. 3:30 Understanding the predecessor: The Budapest Convention
  4. 4:00 Authoritarian countries' push against human rights safeguards
  5. 6:00 Potential for treaty misuse against dissidents and researchers

The UN Cybercrime Treaty is Final, Here's What You Need to Know

Speakers: Kurt Opsahl, Special Counsel, Electronic Frontier Foundation; Policy Council, Filecoin Foundation

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=tPbbMPjFKjA

Overview

Kurt Opsahl's ShmooCon talk, "The UN Cybercrime Treaty is Final, Here's What You Need to Know," provides a critical analysis of the newly finalized United Nations Convention on Cybercrime. This treaty, initiated in 2019 at the behest of Russia and China, aims to either supersede or significantly expand upon the existing Budapest Convention on Cybercrime. Opsahl, an internet lawyer with extensive experience at the Electronic Frontier Foundation (EFF) and the Filecoin Foundation, dissects the treaty's provisions, highlighting its profound implications for civil liberties, human rights, and the crucial work of independent security researchers globally.

The talk serves as an urgent call to action for the cybersecurity community, emphasizing how this international legal framework could be exploited by authoritarian regimes. Opsahl meticulously details how optional safeguards within the treaty could lead to the criminalization of legitimate security research, privacy-enhancing technologies, and even common digital practices like password sharing. His analysis underscores the potential for the treaty to backdoor problematic policies into national laws, creating a less secure and less free global digital landscape.

Background

▶ Watch: Introduction and UN Cybercrime Treaty overview (0:00)

The genesis of the UN Cybercrime Treaty traces back to a 2019 request from Russia to the UN General Assembly, leading to the establishment of an ad hoc committee tasked with drafting a new cybercrime convention. This process, spanning five years of intense negotiations, was framed as an effort to update and broaden the reach of international cybercrime law, particularly for countries lacking robust domestic legislation. However, from its inception, the initiative was viewed with skepticism by civil liberties advocates due to the driving forces behind it: nations like Russia and China, often perceived as having less regard for human rights and individual freedoms.

The existing benchmark, the Budapest Convention on Cybercrime, established in 2001 by the Council of Europe, is widely considered a "Western" treaty, albeit with over 70 signatory nations, including the United States. While not perfect, it incorporates certain human rights safeguards. The new UN treaty, by contrast, emerged from a different philosophical starting point. Key debates during its negotiation centered on whether to pursue a "skinny" (narrowly targeted) or "broad" (wide-ranging) treaty, and crucially, whether to incorporate or largely ignore civil liberties concerns.

Authoritarian states pushing for the new treaty had several objectives. Firstly, they sought to minimize or eliminate human rights protections, viewing them as instruments for "Western Democratic countries to interfere with their internal affairs" [04:20]. A stark illustration of this came from Iran, which proposed removing all human rights safeguards, garnering 25 votes in support. Secondly, these nations desired streamlined mechanisms for obtaining content data and traffic data from other countries, particularly from Western nations where many major tech companies and their data reside. This desire for cross-border data access, often bypassing rigorous legal review, was a significant driver.

Civil liberties groups voiced serious concerns throughout the negotiation process. A primary worry was the potential for the treaty to be used in bad faith to target political opposition figures or dissidents. By labeling their legitimate criticism as "criminal," regimes could then demand information about them from other jurisdictions, circumventing protections for freedom of expression [06:00]. Another critical concern for the technical community was the lack of clear exceptions and limitations for good-faith security research. Activities like vulnerability discovery, penetration testing, and disclosure, which are essential for improving global cybersecurity, can often "look like crime" [06:40] if not explicitly protected. Without such safeguards, researchers risk criminalization for activities vital to collective security.

Furthermore, there was a significant debate over the scope of "cybercrime": whether it should be limited to crimes against computers (e.g., unauthorized access, data interference) or expand to crimes involving computers (where a computer is merely a tool in a broader crime). An early draft of the treaty, for instance, included 34 offenses that would criminalize forms of speech, such as using a computer to spread "extremism" or "desecration of religious values" [08:00]. This concept of content crimes was a major red flag for civil libertarians, as "extremism" can be a subjective label used to suppress political dissent.

Key Findings

▶ Watch: How the UN Cybercrime Treaty started and key debates (2:00)

Despite the strong push from authoritarian states, the final draft of the UN Cybercrime Treaty saw some critical, albeit partial, victories for civil liberties advocates. Notably, two crucial provisions relating to human rights safeguards were retained, despite significant opposition. One article explicitly states that "nothing in the convention shall be interpreted as permitting the suppression of Human Rights or fundamental freedoms" [09:00]. Additionally, some conditions and safeguards for search and surveillance were included, providing a legal "hook" to challenge abuse, even if they were deemed insufficient by many. Crucially, the contentious content crimes, such as those criminalizing extremism or desecration of religious values, were not included in the main body of the treaty, though this victory is recognized as temporary.

The very nature of international treaties presents a complex dynamic, as they can circumvent national political processes. Once ratified, treaties obligate signatory nations to pass conforming domestic laws, potentially "backdooring bad policy" [10:40] that might not pass through a country's regular legislative channels. Opsahl draws a parallel to the WIPO (World Intellectual Property Organization) treaties in the 1990s, which led to provisions like those in the Digital Millennium Copyright Act (DMCA) in the US, subsequently interfering with certain forms of security research. The pressure on negotiators to produce any treaty after years of work also contributes to compromises that may not fully protect rights.

Regarding the United States' position, a statement issued after the treaty's passage through the UN General Assembly indicated that the US is "unlikely to sign or ratify this treaty unless they saw meaningful human rights" implementation by other signatories [14:00]. Furthermore, the US declared it would "not execute requests for content and data for the purposes of enabling human rights abuses such as impeding freedom of expression" [14:40]. However, Opsahl cautions that this statement is "in no way binding on the next Administration," highlighting the fragility of such commitments.

A critical analytical lens for understanding the treaty's impact is the distinction between "shall" and "may" provisions. "Shall" denotes mandatory actions for signatory states, while "may" indicates optional provisions. Unfortunately, many of the key safeguards and limitations designed to protect civil liberties and legitimate activities are framed as "may" provisions, allowing countries to choose whether to adopt them. This flexibility, while intended to attract more signatories, simultaneously creates opportunities for states to implement the treaty in ways that undermine human rights and security research.

Technical Deep Dive

▶ Watch: Understanding the predecessor: The Budapest Convention (3:30)

The UN Cybercrime Treaty introduces a broad definitional framework and a series of core offenses, investigatory powers, and cooperation mechanisms, each with significant technical and legal implications.

1. Definitions:

  • Information and Communications Technology Systems (ICT systems): This definition is exceptionally broad, encompassing "any device or group of interconnected or related devices, one or more of which, pursuant to a program, performs automatic processing of electronic data" [16:00]. It aims to capture virtually any computer-like device that gathers, stores, or processes electronic data.
  • Service Provider: Equally expansive, it includes "any public or private entity that provides users of its service with the ability to communicate by means of an ICT system or processes or stores electronic data for such system or for the system's users" [16:40]. This covers not only traditional ISPs but potentially any entity managing data for users, extending far beyond typical network service providers.
  • Traffic Data: Defined as "any electronic data relating to a communication by means of an ICT system, indicating the origin, destination, route, time, date, size, duration or type of an underlying service, but not the content of the communication" [17:40]. Opsahl emphasizes that even this metadata can reveal significant information, citing the example of a call from the Golden Gate Bridge to a suicide prevention hotline.
  • Content Data: This refers to "the substance of the communication," which typically receives higher levels of protection due to its direct insight into private exchanges.

2. Key Offenses (Articles 7-10): These are the core cybercrime provisions, to which many other parts of the treaty refer.

  • Illegal Access (Article 7): This is the treaty's equivalent of the US Computer Fraud and Abuse Act (CFAA), criminalizing intentionally accessing an ICT system "without right" [19:00]. Crucially, countries may opt to include requirements that this access must involve "infringing security measures" and be done with "the intent of obtaining data or a dishonest Criminal Intent" [19:20]. Opsahl stresses the vital importance of these optional clauses. Without "infringing security measures," simply violating a website's terms of service could be deemed illegal access, a battle hard-fought and largely won in US Supreme Court cases like Van Buren v. United States. The "dishonest or Criminal Intent" clause is equally essential, as it provides a strong defense for good-faith security researchers who operate without malicious intent. Without it, independent research could be easily misconstrued as criminal.
  • Illegal Interception (Article 8): This provision addresses unauthorized wiretapping or electronic communications interception. While it commendably limits the scope to interception "by technical means," the critical "dishonest or Criminal Intent" clause is again optional. Its absence could allow for the abuse of this provision against individuals whose communications are intercepted without malicious intent, but perhaps with political motivations.
  • Interference with Electronic Data (Article 9): This covers the damaging, deletion, deterioration, alteration, or suppression of electronic data. A crucial "may" provision allows countries to require that such interference results in "significant harm" [22:20]. Opsahl warns that without this "significant harm" threshold, even minor alterations or actions like content moderation (which some bad-faith actors might frame as "suppressing information") could be criminalized, blurring lines with content-related offenses.
  • Interference with an ICT System (Article 10): This criminalizes the "serious hindering of the functioning of an ICT system" [24:00]. Fortunately, the inclusion of "serious" in this mandatory provision provides a necessary limit, mitigating some of the potential for misuse compared to a broader "hindering" clause.

3. Related Crimes:

  • Misuse of Devices (Article 11): This provision targets the obtaining, production, sale, procurement, import, distribution, or making available of devices (including software and passwords) primarily designed or adapted for committing the key offenses. This is a highly sensitive area for the security community. While it includes a saving grace requiring "the intent [for the device] to be used for the purpose of committing" [26:00] those offenses, this intent can be difficult to prove or defend against, especially if a researcher is "busted in the meantime" before disclosing.
  • An exception for "authorized testing or protection of information and communication technology system" is included. This is good for contracted penetration testers but leaves independent researchers, bug bounty hunters, or those testing systems where the vendor is uncooperative, vulnerable.
  • Opsahl highlights the danger to password sharing, citing the Netflix example. What is often a commercial dispute or a widely tolerated social practice could be criminalized, potentially turning "millions of people into computer criminals" [28:20].
  • The provision also threatens the use of AI agents or other third-party tools that operate on a user's behalf on online services. Companies like Facebook have historically sued such agents, framing their use as unauthorized access, even when they aim to enhance user privacy or convenience. Criminalizing such tools would further empower companies at the expense of user agency.
  • Forgery (Article 12): This covers inauthentic data created with the intent of being acted upon for legal purposes as if authentic. The optional "intent to defraud or dishonest intent" is critical. Without it, legitimate activities like using VPNs or Tor (which provide an "inauthentic IP address" for privacy or to bypass geo-restrictions) or researcher tools that modify user agents to study discrimination or censorship, could be criminalized as they involve presenting inauthentic data for "legal purposes" (e.g., jurisdiction for streaming services).
  • Theft or Fraud (Article 13): This provision is broad, criminalizing "any deception as a factual circumstance made through an ICT system" that causes someone to act or omit to act, resulting in a gain of money or property. Opsahl notes its dangerous proximity to content crimes, as it could potentially encompass misleading advertising or even false emails. The term "fraudulent" does much of the work here, but without clear boundaries, it risks criminalizing a vast array of online speech that is not directly related to hacking.

4. Investigatory Powers: The treaty outlines a range of investigatory powers, similar to US laws like the Electronic Communications Privacy Act (ECPA) and the Wiretap Act. However, critical safeguards such as judicial review, the requirement for probable cause to obtain warrants, and an effective path to challenge these orders are often presented as optional "may" provisions. While a broad safeguard for "the protection of Human Rights according with obligations under international human rights law" is included, its lack of detail makes it susceptible to bad-faith interpretation by countries with poor human rights records.

5. Technical Assistance: This is one of the most troubling aspects. Countries can "order any person who has knowledge about the functioning of the ICT system in question, the network component parts, or measures applied to protect the data (e.g., encryption) to provide as is reasonable the necessary information to enable the search and seizure" [36:00].

  • "Reasonable" is undefined and will be subject to interpretation.
  • This does not explicitly mandate breaking encryption, but it does require providing information that could help governments break it. This could lead to less secure systems.
  • The phrase "any person who has knowledge" is incredibly broad, potentially encompassing open-source developers, academic researchers, or independent experts, not just company employees.
  • Combined with cross-border cooperation, this means an individual could be compelled to provide information to a foreign government that might abuse it, even if their own government would refuse such a request. The treaty's goal to "streamline processes and speed up investigations" [39:00] often comes at the cost of thorough review mechanisms present in existing Mutual Legal Assistance Treaties (MLATs), increasing the risk of abuse.

6. Jurisdiction: The treaty mandates jurisdiction if an offense is committed in a state's territory or on its flagged vessels/aircraft. However, "may" provisions allow for broader jurisdiction, including offenses committed "against or by a national" (wherever they are) or, most dangerously, "against the state" [41:20]. If content-related crimes are introduced later, this "against the state" clause could allow regimes to claim jurisdiction over dissidents globally.

Demo / Proof of Concept

▶ Watch: Authoritarian countries' push against human rights safeguards (4:00)

This technical article is based on a policy and legal analysis talk. As such, the speaker, Kurt Opsahl, did not present a live demo or a proof of concept during his presentation. His focus was on dissecting the legal text of the UN Cybercrime Treaty and discussing its potential implications.

Defensive Implications

▶ Watch: Potential for treaty misuse against dissidents and researchers (6:00)

For security professionals and policymakers, the UN Cybercrime Treaty presents a complex landscape requiring proactive engagement and vigilance. The most critical defensive implication is the urgent need for countries to adopt all "may" provisions that incorporate safeguards for civil liberties and legitimate security research into their domestic implementing legislation. This includes:

  1. Mandating "Infringing Security Measures" for Illegal Access: National laws should explicitly define unauthorized access as requiring the circumvention of technical security measures, distinguishing it from mere terms-of-service violations. This protects the precedent established in cases like Van Buren.
  2. Requiring "Dishonest or Criminal Intent": For offenses like illegal access, interception, misuse of devices, and forgery, national legislation must stipulate that a prosecutor must prove dishonest or criminal intent. This is paramount for protecting good-faith security researchers, penetration testers, and privacy advocates from criminalization. Without it, independent vulnerability research, which is crucial for improving global cybersecurity, could be severely curtailed.
  3. Establishing "Significant Harm" for Data Interference: To prevent the criminalization of minor data alterations or even content moderation, domestic laws should require proof of "significant harm" for data interference offenses.
  4. Implementing Robust Safeguards for Investigatory Powers: Countries should ensure their domestic laws include strong protections such as judicial review, probable cause standards for warrants, and clear mechanisms for individuals to challenge requests for data or technical assistance. These safeguards must be detailed and binding, not vague references to international human rights law.
  5. Protecting Security Tools and Practices: The community must advocate against the criminalization of legitimate security tools and practices. This includes ensuring that "misuse of devices" provisions do not unduly target pen-testing tools or the sharing of passwords for non-malicious purposes. Practices like using VPNs or Tor for privacy and security, or employing AI agents for personal data management, must not be criminalized under forgery or other broad provisions.
  6. Opposing the "Additional Protocol" for Content Crimes: The cybersecurity community must actively and unequivocally oppose any future "additional protocol" to the treaty that seeks to reintroduce content-related crimes like "extremism" or "desecration of religious values." These provisions are ripe for abuse by authoritarian regimes to suppress dissent and criminalize free speech. Opsahl's stark advice: "kill that with fire" [44:30].
  7. Vigilant Engagement with National Legislators: Given that treaties bypass standard legislative processes, security professionals, civil liberties advocates, and engaged citizens must closely monitor their country's plans for signing and ratifying the treaty and, crucially, for drafting the implementing legislation. Direct communication with legislative representatives, emphasizing the technical and societal implications, is essential to ensure that optional safeguards are adopted and abuses are prevented.

The treaty's broad definitions and optional safeguards create a high degree of uncertainty. Defenders must push for clear, rights-respecting interpretations and implementations at every stage to prevent a chilling effect on legitimate security work and to protect fundamental digital rights.

Key Takeaways

  • The new UN Cybercrime Treaty is a problematic and flawed international instrument, largely driven by authoritarian states with intentions to expand surveillance and control.
  • Crucial safeguards for civil liberties, human rights, and legitimate security research are often optional ("may" provisions), creating significant risks if countries choose not to adopt them in their domestic laws.
  • The treaty's broad definitions of "ICT systems," "service providers," and offenses like "illegal access" and "misuse of devices" could lead to the criminalization of independent security research, pen-testing tools, password sharing, AI agents, and privacy-enhancing technologies like VPNs/Tor.
  • Investigatory powers and technical assistance provisions are expansive, potentially requiring "anyone with knowledge" to provide information that could aid in breaking security systems, and they often lack mandatory, detailed safeguards like judicial review or probable cause.
  • While content crimes were excluded from the main treaty, a future "additional protocol" is intended to reintroduce them, posing a significant threat to freedom of expression and political dissent globally.
  • The cybersecurity community and civil liberties advocates must actively oppose the signing of this treaty by rights-respecting countries and, where it is signed, vigorously advocate for the strongest possible implementation of optional safeguards in national legislation.

About the Speaker(s)

Kurt Opsahl is a highly respected internet lawyer with a distinguished career spanning decades at the intersection of technology, law, and civil liberties. He began his legal practice in the 1990s, representing early internet companies during the dot-com boom. Opsahl then joined the Electronic Frontier Foundation (EFF), a leading non-profit organization defending digital rights, where he served as General Counsel. In this role, he notably led the Coders Rights Project, dedicated to defending hackers and security researchers who faced legal trouble for their legitimate work and presentations. Currently, he serves as a Special Counsel with the EFF in a volunteer capacity, continuing his advocacy. Additionally, Opsahl is involved with the Security Researcher Legal Defense Fund, which provides grants to security researchers needing legal assistance. He is also a Policy Council with the Filecoin Foundation, where his work focuses on cybersecurity and civil liberties policy. His extensive experience and deep understanding of both technology and law make him a critical voice on issues such as the UN Cybercrime Treaty.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This session delivered a crucial, unvarnished breakdown of the finalized UN Cybercrime Treaty. The speaker, drawing on deep legal expertise, meticulously dissected the treaty's language, exposing the optional safeguards and broad definitions that could easily be exploited by authoritarian regimes to criminalize legitimate security research, privacy tools, and even basic digital activities. While the underlying legal battles might feel familiar, the detailed analysis of this new, globally impactful document is essential for anyone operating in the cybersecurity space.

Heather Calloway (CISO) — STRONG ACCEPT

Kurt Opsahl's analysis of the UN Cybercrime Treaty is a critical piece of intelligence for any CISO or security leader operating in a global context. He meticulously dissects a complex legal instrument, highlighting its profound implications for legitimate security research, civil liberties, and the operational boundaries of enterprise security programs. The distinction between 'shall' and 'may' provisions is a crucial insight, laying bare the governance challenge and the imperative for proactive engagement with national policymakers to safeguard essential technical practices and prevent the criminalization of vital defensive work.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)